npm package trust score

prettier

npm · 106M/week · 9.5 years old

82/ 100
CRITICAL
npm publishers11
Weekly downloads106M
Package age9.5 years
Last published4d ago
GitHub contributors35
SLSA provenanceNo
Trusted PublishingNo
OpenSSF Scorecard6.6/10
GradeA

Risk flags

CRITICAL: sole active npm publisher + >10M/wkWARN: 11 dormant publishers with current scope access — jlongster (114mo inactive), vjeux (107mo inactive), azz (102mo inactive), suchipi (98mo inactive), ikatyang (90mo inactive), duailibe (86mo inactive), lydell (80mo inactive), thorn0 (62mo inactive), sosukesuzuki (52mo inactive), fisker (38mo inactive), prettier-bot (13mo inactive)

prettier has a single npm publisher with 106M weekly downloads. This is the exact attack profile that enabled the axios compromise (March 2026) and the LiteLLM supply chain attack. A stolen credential gives an attacker publish access to a package running on millions of machines. GitHub contributors (35) don't have npm publish rights — only the publisher does.

Score breakdown

Five behavioral dimensions. Each measured from public registry data, not self-reported.

Longevity
25/25
Download momentum
22/25
Release consistency
20/20
Publisher depth
0/15
GitHub backing
15/15
Trusted Publishing
0/2

What this score measures

The Commit trust score measures behavioral commitment — signals that are hard to fake. Unlike stars, READMEs, or download counts, these signals capture how a package is actually maintained.

Related reading

Monitor this package

prettier has concentrated publish-access risk. Get alerted when its publisher count, release cadence, or risk score changes.

Free: 200 audits/day · Paid from Developer ($15/mo): monitoring, batch API, email alerts

Use this data

CLI

npx proof-of-commitment prettier

MCP (Claude, Cursor, Windsurf)

{ "mcpServers": { "commit": { "type": "streamable-http", "url": "https://poc-backend.amdal-dev.workers.dev/mcp" } } }

README badge

![Commit Trust](https://poc-backend.amdal-dev.workers.dev/badge/npm/prettier)

prettier commit trust badge

REST API

curl -X POST https://poc-backend.amdal-dev.workers.dev/api/audit -H "Content-Type: application/json" -d '{"packages":["prettier"]}'